Description
Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Premiere Pro has a heap-based buffer overflow vulnerability that can lead to arbitrary code execution when a user opens a crafted file. This overflow, identified as CWE-122, occurs during processing of certain data within the application, potentially allowing an attacker to run code with the privileges of the current user.

Affected Systems

Adobe Premiere Pro (all versions) – the CVE notes that any installed instance of Premiere Pro is affected; specific versions are not listed in the advisory.

Risk and Exploitability

The CVSS score of 7.8 rates the vulnerability as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction; an attacker would need to supply a malicious file that the victim opens, which may limit the attack surface but still allows potential compromise when unsuspecting users engage.

Generated by OpenCVE AI on July 31, 2026 at 05:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Premiere Pro to the latest version as per the APSB26-76 security bulletin.
  • Configure the software to run under a non-administrative user account to limit the potential damage if execution occurs.
  • Prevent opening of unknown or suspicious files by using controlled file import procedures or scanning files with up-to-date antivirus before opening.

Generated by OpenCVE AI on July 31, 2026 at 05:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe premiere
Vendors & Products Adobe
Adobe premiere

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Premiere Pro | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:38:05.662Z

Reserved: 2026-05-21T15:28:38.132Z

Link: CVE-2026-48269

cve-icon Vulnrichment

Updated: 2026-07-15T10:37:59.807Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow